Managed XDR

6736c0de4276f.exe — malware analysis report

File info

Filename
6736c0de4276f.exe
File type
PE32+ executable (console) x86-64, for MS Windows
File size
362.4 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
8b9b8a6c297fb5803f7ea36e2d9c8f86749b81cf
SHA256
fecb9a645d2cb0440fa90e3cdeeb1673ae68599ccbbee2662135987a4432097b
MD5
08e8d2b558877e0263fadbefe871fa86

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
pe_overlay: PE file contains overlay